ThreatPaper
Unverified

ShinyHunters obtained the private keys to Clop's Tor onion service

Assessment

This is the most consequential of ShinyHunters' claims: possession of Clop's onion service private keys would let the group stand up a site at Clop's exact existing onion address on its own infrastructure, as ShinyHunters itself argued ('if they kick us out it wouldn't matter at all because we control the private keys to host the same exact onion URL'). BleepingComputer independently confirmed the defacement of Clop's leak site and the initial uploaded taunt file, but states explicitly that it has not independently verified ShinyHunters' claims to have stolen server logs, source code, or the onion private keys. A reader repeating 'ShinyHunters has Clop's onion keys' as fact would be treating an unverified assertion by an extortion actor — one with a direct incentive to overstate what it holds — as established.

Where this claim appeared

ShinyHunters (via BleepingComputer) · 2026-09-19

https://www.bleepingcomputer.com/news/security/shinyhunters-hacks-clop-leak-site-threatens-to-extort-ransomware-gang/

What “Unverified” means

Widely repeated, but no supporting evidence was located. This is not a statement that the claim is false — it is a statement that nothing published supports it, which is a different and more common problem.

2 of 5 · rating scale

Assessed in

ShinyHunters defaces Clop's leak site and claims its onion keys — a cybercrime feud, and what's actually confirmed

Think this assessment is wrong? Report an error.